SECOPS-PRO · Question #74
You are a lead security engineer at a large enterprise, tasked with optimizing the organization's threat intelligence pipeline for maximum effectiveness against polymorphic malware and advanced…
The correct answer is B. Deploy Palo Alto Networks NGFWs with integrated WildFire cloud subscription for automated. This question focuses on building an optimal threat intelligence pipeline for advanced threats. Option B provides the most comprehensive and effective approach. Palo Alto Networks NGFWs with WildFire offer automated, real-time dynamic analysis and signature generation, directly…
Question
You are a lead security engineer at a large enterprise, tasked with optimizing the organization's threat intelligence pipeline for maximum effectiveness against polymorphic malware and advanced persistent threats (APTs). The current setup primarily relies on basic SIEM correlation and generic firewall rules. Your goal is to implement a solution that provides real-time, context- rich intelligence, automates detection of unknown threats, and enables proactive defense. Which of the following architectural and operational decisions would be most aligned with achieving these objectives?
Options
- AIntegrate all network logs with VirusTotal's public API for continuous hash lookups, and manually
- BDeploy Palo Alto Networks NGFWs with integrated WildFire cloud subscription for automated
- CPurchase an open-source sandbox solution and develop custom Python scripts to parse its output
- DFocus exclusively on endpoint protection platforms (EPPs) with AI-driven behavioral analysis, as
- EImplement an extensive honeypot network to capture malware samples, then manually analyze
How the community answered
(36 responses)- A3% (1)
- B72% (26)
- C14% (5)
- D6% (2)
- E6% (2)
Explanation
This question focuses on building an optimal threat intelligence pipeline for advanced threats. Option B provides the most comprehensive and effective approach. Palo Alto Networks NGFWs with WildFire offer automated, real-time dynamic analysis and signature generation, directly protecting the network from unknown threats, including polymorphic malware. Unit 42's premium intelligence provides the deep context on APTs, their TTPs, and campaigns, which is vital for proactive defense and understanding the adversary. Integrating these into a SIEM allows for enhanced correlation and a holistic view of the threat landscape, maximizing effectiveness. This leverages the synergistic capabilities of Palo Alto Networks' core products for a robust threat intelligence ecosystem.
Topics
Community Discussion
No community discussion yet for this question.